Hello,
I renewed the SSL certificat 3 month ago with the command below :
cp -r /etc/letsencrypt/ /etc/letsencrypt16102018 ./certbot-auto renew
But when i try to renew amoung 3 month it does'nt work.
Thanks for advance for your help.
My domain is: silex-ip.com
I ran this command:
- /etc/letsencrypt# certbot --apache
- /etc/letsencrypt# letsencrypt renew
- /etc/letsencrypt# ./certbot-auto renew --dry-run
It produced this output:
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator apache, Installer apache
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.orgWhich names would you like to activate HTTPS for?
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 1
Cert is due for renewal, auto-renewing...
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for www.silex-ip.com
Waiting for verification...
Cleaning up challenges
Failed authorization procedure. www.silex-ip.com (http-01): urn:ietf:params:acme:error:unauthorized ::
The client lacks sufficient authorization :: Invalid response from
http://www.silex-ip.com/.well-known/acme-challenge/sMagleQpp4uZDTJSvRy7yXnecV6eIqrMYvz1PDnnTE0:
"\n\n403 Forbidden\n\nForbidden
\n<p"IMPORTANT NOTES:
The following errors were reported by the server:
Domain: www.silex-ip.com
Type: unauthorized
Detail: Invalid response from
http://www.silex-ip.com/.well-known/acme-challenge/sMagleQpp4uZDTJSvRy7yXnecV6eIqrMYvz1PDnnTE0:
"\n\n403
Forbidden\n\nForbidden
\n<p"To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
Blockquote
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/www.silex-ip.com.conf
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator apache, Installer apache
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for www.silex-ip.com
Waiting for verification...
Cleaning up challenges
Attempting to renew cert (www.silex-ip.com) from /etc/letsencrypt/renewal/www.silex-ip.com.conf produced an unexpected error: Failed authorization procedure. www.silex-ip.com (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://www.silex-ip.com/.well-known/acme-challenge/blbLso5qZ3gwyDmO8HZRHWN3XrWcPC1KKbR2oy3IYv4: "\n\n403 Forbidden\n\nForbidden
\n<p". Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/www.silex-ip.com/fullchain.pem (failure)
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/www.silex-ip.com/fullchain.pem (failure)
1 renew failure(s), 0 parse failure(s)
IMPORTANT NOTES:
The following errors were reported by the server:
Domain: www.silex-ip.com
Type: unauthorized
Detail: Invalid response from
http://www.silex-ip.com/.well-known/acme-challenge/blbLso5qZ3gwyDmO8HZRHWN3XrWcPC1KKbR2oy3IYv4:
"\n\n403
Forbidden\n\nForbidden
\n<p"To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Processing /etc/letsencrypt/renewal/www.silex-ip.com.conf
Cert is due for renewal, auto-renewing...
Plugins selected: Authenticator apache, Installer apache
Renewing an existing certificate
Performing the following challenges:
http-01 challenge for www.silex-ip.com
Waiting for verification...
Cleaning up challenges
Attempting to renew cert (www.domain-name.com) from /etc/letsencrypt/renewal/www.silex-ip.com.conf produced an unexpected error: Failed authorization procedure. www.domain-name.com (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://www.domain-name.com/.well-known/acme-challenge/o4StqxWfBd8E63RLymnp3wm1mdigSWjdCmZh1Y7vQ4U: "\n\n403 Forbidden\n\nForbidden
\n<p". Skipping.
All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/www.silex-ip.com/fullchain.pem (failure)
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates below have not been saved.)All renewal attempts failed. The following certs could not be renewed:
/etc/letsencrypt/live/www.silex-ip.com/fullchain.pem (failure)
** DRY RUN: simulating 'certbot renew' close to cert expiry
** (The test certificates above have not been saved.)
1 renew failure(s), 0 parse failure(s)
IMPORTANT NOTES:
The following errors were reported by the server:
Domain: domain-name
Type: unauthorized
Detail: Invalid response from
http://www.silex-ip.com/.well-known/acme-challenge/o4StqxWfBd8E63RLymnp3wm1mdigSWjdCmZh1Y7vQ4U:
"\n\n403
Forbidden\n\nForbidden
\n<p"To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
My web server is (include version): Apache/2.4.18 (Ubuntu)
The operating system my web server runs on is (include version): Ubuntu 16.04.4 LT
I can login to a root shell on my machine (yes or no, or I don't know): yes
/etc/letsencrypt/live/www.silex-ip.com# ll
total 12
drwxr-xr-x 2 root root 4096 Oct 16 13:14 ./
drwx------ 3 root root 4096 Jul 21 17:56 ../
lrwxrwxrwx 1 root root 40 Oct 16 13:14 cert.pem -> ../../archive/www.silex-ip.com/cert2.pem
lrwxrwxrwx 1 root root 41 Oct 16 13:14 chain.pem -> ../../archive/www.silex-ip.com/chain2.pem
lrwxrwxrwx 1 root root 45 Oct 16 13:14 fullchain.pem -> ../../archive/www.silex-ip.com/fullchain2.pem
lrwxrwxrwx 1 root root 43 Oct 16 13:14 privkey.pem -> ../../archive/www.silex-ip.com/privkey2.pem
-rw-r--r-- 1 root root 682 Jul 21 17:56 README
/etc/letsencrypt/archive/www.silex-ip.com# ll
total 40
drwxr-xr-x 2 root root 4096 Oct 16 13:14 ./
drwx------ 3 root root 4096 Jul 21 17:56 ../
-rw-r--r-- 1 root root 2155 Jul 21 17:56 cert1.pem
-rw-r--r-- 1 root root 2159 Oct 16 13:14 cert2.pem
-rw-r--r-- 1 root root 1647 Jul 21 17:56 chain1.pem
-rw-r--r-- 1 root root 1647 Oct 16 13:14 chain2.pem
-rw-r--r-- 1 root root 3802 Jul 21 17:56 fullchain1.pem
-rw-r--r-- 1 root root 3806 Oct 16 13:14 fullchain2.pem
-rw-r--r-- 1 root root 1704 Jul 21 17:56 privkey1.pem
-rw-r--r-- 1 root root 1708 Oct 16 13:14 privkey2.pem
Also i created next folder and file in document root :
.well-known/acme-challenge/test
It is reachable only if i comment the next line in the configuration file :
<IfModule mod_rewrite.c>
Options -MultiViews
RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
##RewriteRule ^(.*)$ app.php [QSA,L]
</IfModule>
</Directory>